Backplane Filtering Logic Device for Cyber-Attack Mitigation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional approaches to maintaining resilience of control systems are insufficient to protect against simultaneous cyber-attacks, as they rely on identical redundancy that may not effectively counter intelligent adversary attacks.

Innovation Solution

Incorporating a logic device between control system modules and the backplane that filters communications based on trustworthiness, isolates compromised modules, and assumes processing unit operations to provide diverse redundancy, thereby preventing a single attack from subverting the entire system.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If identical redundancy is implemented in control systems, then resilience to random or physical failures is improved, but protection against simultaneous cyber-attacks is insufficient

Engineering Contradiction:
Improveresilience to random or physical failuresVSAvoidvulnerability to cyber-attacks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies asymmetry by introducing a logic device with different functional characteristics than the standard identical redundancy components. The logic device performs diverse functions including filtering communications, isolating compromised modules, and assuming processing unit operations, thereby creating non-identical redundancy that resists simultaneous cyber-attacks while maintaining resilience to random failures.

Inventive Principle:
Principle #4Asymmetry

Solution Approach 2:

The patent changes the parameters of redundancy from identical copies to diverse functional implementations. The logic device modifies communication parameters by filtering based on trustworthiness, isolating compromised modules, and emulating processing unit logic, thus transforming the redundancy mechanism to address cyber-threats while preserving physical failure resilience.

Inventive Principle:
Principle #35Parameter changes

2Stability of the object's composition

If conventional redundancy approaches are used, then system operation is maintained during single component failures, but simultaneous cyber-attacks can compromise the entire system

Engineering Contradiction:
Improvesystem operation during component failureVSAvoidprotection against simultaneous cyber-attacks
Core Design Contradiction:
Stability of the object's compositionVSReliability

Solution Approach 1:

The logic device serves as an intermediary component positioned between control system modules and the backplane. It mediates communications by filtering harmful signals, isolating compromised modules, and assuming processing unit operations, thereby maintaining system stability during both physical failures and cyber-attacks through its intermediate protective function.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the control system by introducing a dedicated logic device that handles security functions separately from the main processing units. This segmentation allows the logic device to independently filter communications, isolate compromised modules, and assume processing operations, preventing cyber-attacks from compromising the entire system while maintaining operational stability.

Inventive Principle:
Principle #1Segmentation

3Reliability

If a logic device is incorporated between modules and the backplane, then active mitigation of cyber-attacks is achieved, but device complexity increases

Engineering Contradiction:
Improveactive mitigation of cyber-attacksVSAvoidcontrol system architecture
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The logic device embodies multi-functionality by performing diverse operations including filtering communications based on trustworthiness, isolating compromised modules, and assuming processing unit operations. This universal approach consolidates multiple security functions into a single device, achieving active cyber-attack mitigation while managing architectural complexity through functional integration.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10375106B1Backplane filtering and firewalls
Publication Date: 2019.08.06 NATIONAL TECHNOLOGY & ENGINEERING SOLUTIONS OF SANDIA LLC
  • US10375106B1 patent drawing
  • US10375106B1 patent drawing
  • US10375106B1 patent drawing

AI summary

Described herein are various technologies for providing active mitigation of cyber-attacks against industrial and other control systems. A filtering device is connected to a backplane of a control system and receives communications from various modules of the control system. The filter device analyzes the received communications and determines whether they are genuine and permissible communications for the control system. Validated signals are output to a communications bus of the control system by the filter device, while impermissible communications are blocked. The filter device can be interposed between the modules of the control system and the backplane, or the filter device can be included as a component of a control system backplane.